CVE-2026-0301: Information disclosure vulnerability in Palo Alto PAN-OS
Palo Alto PAN-OS 11.1.8 contains an information disclosure vulnerability that affects instances with a customized response page where URL filtering is enabled. The vulnerability allows an attacker to display data of random memory locations over the block page by repeatedly querying websites that are blocked by the firewall. Furthermore, the vulnerability allows an attacker to write to a fixed offset in memory by manipulating the URL query string, so that the input is reflected on the block page.
The vulnerability was acknowledged and completely fixed by Palo Alto within 369 days.
CVSS Score
6.3 (CVSS v4)
CVSS Vector String
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
/E:U/AU:N/R:U/V:D/RE:M/U:Amber
CVSS vector string (cirosec):
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:N/SA:N
Affected Version
PAN-OS < 10.2.8, PAN-OS < 11.1.16-h1, Prisma Access < 10.2.10
Fixed Version
PAN-OS >= 10.2.8, PAN-OS >= 11.1.16-h1, Prisma Access >= 10.2.10
References
https://security.paloaltonetworks.com/CVE-2026-0301
Credits
Jan Breig (cirosec GmbH)
Timeline
2025-08-08
Vendor was contacted and informed about the vulnerability via email.
2025-08-09
Initial response received from vendor. Vendor acknowledged the vulnerability and forwarded the information to product team for review. Internal tracking ID PAN-299253
2026-02-02
Second attempt was made to contact vendor via email.
2026-04-27
Vendor was contacted and informed about upcoming disclosure of the vulnerability.
2026-04-27
Response received from vendor. Vendor confirmed a partial fix and requested to postpone the publication until an update is rolled out for all affected products.
2026-08-12
Vendor disclosed the vulnerability and assigned a CVE.